1k Data Breaches Later, the Disclosure Lag Is Worse
- Security
- Privacy
- Regulation
- Developer Tools
The post comes from Troy Hunt, who runs Have I Been Pwned, after loading its 1,000th breach. His point is simple and ugly: despite years of public pressure, regulation, and endless headlines, the lag between a breach happening and users being told is still getting worse. That delay matters because people cannot rotate credentials, freeze credit, or watch for targeted fraud until long after attackers already have a head start.
If you run a product, treat retained personal data as a balance-sheet liability, not a growth asset. If you buy software, ask vendors how fast they disclose incidents, what they actually store, and how quickly they can tell you exactly whose data was exposed.
- troyhunt.com
- Discuss on HN